Back to skill

Security audit

Polymarket Clob Microstructure

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly coherent with its stated trading purpose, but it can run repeatedly with a trading API key and has a fail-open safety check before live trades.

Review carefully before installing or running live. Use a restricted SIMMER_API_KEY with account-side limits, keep the default dry-run mode until tested, pin dependencies to reviewed versions, and change the context check to fail closed before enabling scheduled live trading.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
clawhub.json:4
Finding

Unpinned Third-Party Dependencies Expose the Skill to Supply-Chain Risk

Content
View full analysis
Remediation
View remediation
", "requests==" ] ``` 2. Use a lock file or requirements file containing cryptographic hashes and install with hash verification. 3. Obtain packages only from an explicitly configured, trusted package index. 4. Verify package ownership, release provenance, and signatures where the distribution mechanism supports them. 5. Run automated dependency vulnerability and provenance checks before releases. 6. Review and intentionally approve dependency updates rather than allowing automatic resolution to newly published versions. 7. Restrict the runtime environment so the process has only the filesystem, network, credential, and trading permissions required for this Skill. ]]>

T09 · Insecure Skill Coding Practices

Error
Location
clob_microstructure.py:31
Finding

Pre-Trade Safety Validation Fails Open When Market Context Is Unavailable

Content
View full analysis
0.15: return False, "slippage too high" edge = ctx.get("edge_analysis", {}) if edge.get("recommendation") == "HOLD": return False, "edge below threshold" return True, "ok" except Exception: return True, "context unavailable" ``` The returned approval is consumed immediately before live execution at `clob_microstructure.py:429-445`: ```python ok, reason = check_context(client, sig["market_id"]) if not ok: log.warning("Skipping trade: %s", reason) continue if live: try: result = client.trade( market_id=sig["market_id"], side=side, amount=size, source=TRADE_SOURCE, skill_slug=SKILL_SLUG, reasoning=reasoning, ) log.info("Order placed: %s", json.dumps(result, default=str)[:200]) trades_placed += 1 ``` ### Technical Analysis `check_context()` is intended to block trades when the market has a severe flip-flop warning, excessive slippage, or an edge recommendati ...[truncated 2318 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.